NCA ECC — READINESS REFERENCE

Understand the evidence behind ECC readiness.

This educational page helps teams discuss selected Essential Cybersecurity Controls and identify evidence gaps. It is not a complete legal interpretation, certification, or auditor assessment.

5
high-level ECC domains to understand
Readiness
the purpose of this educational tool
No
certification or auditor attestation

What Is ECC and Why It Matters

The Essential Cybersecurity Controls (ECC-1:2018) define a cybersecurity baseline published by the NCA for relevant organizations in Saudi Arabia. A gap may create regulatory and business risk, but applicability and compliance require qualified review.

A readiness review should connect each relevant control objective to current, reviewable evidence. SOCRoot can help structure that mapping, but it does not claim continuous measurement of every control or certify compliance.

All 5 ECC Domains Covered

Cybersecurity Governance

Policy frameworks, risk ownership, roles and accountability — the foundation everything else is built on.

Cybersecurity Defense

Endpoint protection, vulnerability management, network segmentation, and continuous external scanning.

Cybersecurity Resilience

Incident response plans, business continuity, disaster recovery, and backup integrity testing.

Third-Party Cybersecurity

Vendor risk assessments, contractual cybersecurity requirements, and securing supply chains.

Self-Assessment Checklist

Use this simplified checklist as a conversation starter. Its score is educational and must not be represented as an ECC compliance result.

Simplified Readiness Score

0%

0 / 16 controls

7 critical gaps

Start checking items to explore which evidence may exist.

Educational self-assessment only. This score is not certification, legal advice, or an auditor opinion.

Cybersecurity PolicycriticalGovernance
Roles & ResponsibilitieshighGovernance
Risk ManagementcriticalGovernance
Asset InventorycriticalDefense
Vulnerability ManagementcriticalDefense
Network SecurityhighDefense
Email & Web FilteringhighDefense
Endpoint ProtectioncriticalDefense
Privileged Access ManagementhighDefense
EncryptionhighDefense
Incident Response PlancriticalResilience
Business ContinuityhighResilience
Backup & RecoverycriticalResilience
Vendor Risk AssessmenthighThird-Party
Contractual RequirementsmediumThird-Party
Cloud SecurityhighThird-Party

7 critical controls not implemented

Treat these selections as prompts for evidence review, not as confirmed control failures or a remediation estimate.

Prepare an Authorized Review

A responsible readiness workflow

  • 1

    Initial Gap Analysis

    Agree the applicable control objectives, scope, evidence sources, owners, and exclusions before rating readiness.

  • 2

    Remediation Roadmap

    Record current evidence, missing evidence, uncertainty, and the operational impact of each gap.

  • 3

    Prioritized Improvement Work

    Translate validated gaps into prioritized technical and governance work with accountable owners.

  • 4

    Evidence Package

    Retest improvements and organize evidence for internal review or an independent qualified assessor.

EDUCATIONAL READINESS SUPPORT

Start with scope and evidence

A useful readiness conversation begins with applicable obligations, asset ownership, evidence sources, and the decision the review needs to support.